- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
DMZ Switch
I would love to hear recommendation on what model of Meraki switch we can use as a DMZ switch? We have 2 Palo Alto firewall (High Availability/ HA Setup), and we're using 2 internet lines as well. In the current setup, we are using a Cisco Catalyst 2960c 8-PORT. Since we are planning to replace all the network switch with Meraki, we are thinking to replace as well this DMZ switch.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As a like for like I'd go with an MS130-8 model. You could upgrade to the MS130-8X if you want the possibility of adaptive policy in the future. In reality any Meraki switch can be a DMZ switch as long as you give it access to the Meraki cloud for management and updates.
The only place I personally don't use Meraki switches is on the outside of the firewall where ISP connections need splitting to one or more devices. I would always recommend using either an unmanaged switch, or one with out of band management in that location. Cisco make many small cheap switches for that requirement.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Agreed with @cmr - unless you're doing something particularly special, any Meraki switch should work here.
Whilst not ideal, using Meraki switches to split ISP connections can work.
It's just a PITA if you do something that causes it to lose Internet connectivity.
